What's an AI Inventory?
This video explains why legal teams should build an AI inventory before writing an AI policy, since a policy only governs tools someone remembered to name while an inventory tracks every tool actually in use.
A legal team's first instinct when AI tools start showing up is usually to write a policy: a rule about which tools are allowed. That instinct gets the order backwards. A policy can only govern the tools someone remembered to name in it, and the tools adopted quietly by a team always slip past.
Why a policy alone doesn't close the gap
A policy is a rule about what's allowed, decided in advance. But it only knows about the tools someone thought to write into it. The ones adopted quietly, without anyone flagging them, never make it onto that list, so the policy never actually covers them. What closes that gap isn't a stronger rule, it's a live list of what's actually running.
The four fields that make up an inventory
An AI inventory tracks four things for every tool in use: what it does, what data touches it, who owns it, and a risk tier set by how sensitive that data is. The anchor example in the video is a contract-review tool a litigation team quietly started using, one nobody wrote into any policy because nobody wrote it down anywhere at all. Running that tool through the same four fields as everything else makes it visible instead of letting it keep running unnoticed.
Logged is not the same as cleared
Being entered into the inventory doesn't mean a tool is safe. The risk tier is a flag for review, not a green light. And a list that looks complete today doesn't mean nothing's missing tomorrow, the next tool adopted needs the same four fields before the inventory can call itself current. The core point: you can't govern an AI tool you haven't listed. Build the inventory before you write the policy, because the policy only works once you actually know what it has to cover.
Try it on your own team
List every AI tool your team used this month, drafting help, research search, document review, anything at all. For each one, write down what it does, what data goes through it, and who owns it. If any row comes up blank on "owner," that's the exact gap the inventory just found, the same gap a policy alone would never have caught.
Key takeaways
- A policy only governs tools someone remembered to name in it; quietly adopted tools slip past it every time.
- An inventory tracks four fields per tool: what it does, what data touches it, who owns it, and a risk tier.
- Logging a tool makes it visible, but an entry in the inventory doesn't mean the tool has been cleared as safe.
- A finished-looking inventory can still be incomplete; every newly adopted tool needs the same four fields to keep it current.
- The inventory has to come before the policy, since a policy can't cover tools nobody knew existed.
Who this is for
Legal and compliance teams trying to get ahead of AI tool adoption inside their organization, especially anyone tempted to start with a policy document before first finding out what tools are actually in use.
Chapters
Full transcript(auto-generated, with timestamps)
Do we need an AI policy before we use this?
[0:00]Someone on a legal team asks if they need an AI policy before rolling out a new tool. Wrong first word. What they actually need is an inventory. Lay 'em, take them through it. You could write a
A policy only covers what's named
[0:10]Policy tomorrow, a rule about which AI tools are allowed, but a policy can only govern the tools someone remembered to name in it. The ones adopted quietly slip past every time because the policy never knew they existed. What actually closes that gap isn't a rule about what's allowed, it's a live list of what's actually running. Four things go
Four fields — the anchor
[0:28]In for every tool on that list. What it does, what data touches it, who owns it, and a risk tier set by how sensitive that data is. Watch the Anchor, the contract review tool your litigation team quietly started using last spring. Nobody wrote it into any policy because nobody wrote it down anywhere. That tool goes through the same four
Logged, not cleared
[0:46]Fields as everything else logged, tiered by risk, given an owner, and now it's visible instead of running unnoticed. But an entry doesn't mean the tool is safe. The risk tier is a flag for review, not a green light. And a finished-looking list doesn't mean nothing's missing, either. The next tool adopted tomorrow needs the same four fields before the list can call itself current. You can't govern an AI tool you
Carry-out
[1:07]Haven't listed. Build the inventory before you write the policy. The policy only works once you know what it has to cover.
Your turn
[1:14]Your turn. Here's the prompt. Read it with me. List every AI tool your team used this month. Drafting help, research, search, document review, anything. For each one, write down what it does, what data goes through it, and who owns it. If any row is missing an owner, that's the gap the inventory just found. Lay 'em in for Bear. What's an AI inventory? Lay 'em in for Bear.





